Deploying Kubernetes on Fedora CoreOS with Kubespray, I hit a Kubespray CRI-O read-only file system error partway through the container runtime install. The fix is one inventory variable.
The failing task:
TASK [container-engine/cri-o : Cri-o | create directory for libexec] ******************
fatal: [worker-03]: FAILED! => {"changed": false, "msg": "There was an issue creating /usr/libexec/crio as requested: [Errno 30] Read-only file system: b'/usr/libexec/crio'", "path": "/usr/libexec/crio"}
Why Kubespray’s CRI-O role fails on Fedora CoreOS Link to heading
Fedora CoreOS mounts /usr read-only, so only OS updates can change it. Kubespray’s CRI-O
role sets crio_libexec_dir to /usr/libexec/crio by default and copies conmon,
conmonrs, crun and runc into it, so the first task that creates that directory fails.
This comes from Kubespray’s settings for CRI-O 1.31 and later. Older versions installed
conmon into bin_dir and never touched /usr/libexec.
Fixing the read-only error with crio_libexec_dir Link to heading
The path is a variable, so I override it in the inventory and point it at somewhere writable:
# inventory/<cluster>/group_vars/all/coreos.yml
crio_libexec_dir: "/opt/libexec/crio"
Re-run the playbook. Kubespray installs the binaries into the new directory and writes the
matching conmon and runtime paths into /etc/crio/crio.conf. The crio.service unit
doesn’t reference this directory, so it needs no change.
Checking it worked Link to heading
On a node:
grep conmon /etc/crio/crio.conf
systemctl is-active crio
The conmon line should point at /opt/libexec/crio/conmon, and CRI-O should report
active.